Back to advisories

GitLab Patches Critical Code Injection Vulnerability

GitLab released patches for a critical unauthenticated code injection vulnerability (CVE-2026-19478, CVSS 9.4) in GraphQL directives that allows attackers to modify or delete user data and public projects. A secondary CSRF flaw (CVE-2026-19650) affects the GraphQL multiplex query handler. Versions 18.2 through 19.2 are vulnerable and require immediate patching.

CRITICALAdvisoryAug 18, 2026
Action required
Identify all GitLab CE/EE instances running versions 18.2-19.2 in your environment and upgrade immediately to 18.11.11, 19.0.8, 19.1.6, or 19.2.4. Monitor GitLab API logs for suspicious GraphQL directive activity and unauthenticated data modification attempts targeting projects and user accounts.
Affected products
GitLabGitLab Community EditionGitLab Enterprise Edition